Vulnerabilities (CVE)

Total 398612 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-13290 1 Ohdear 1 Ohdear Integration 2026-06-17 N/A 5.3 MEDIUM
Incorrect Authorization vulnerability in Drupal OhDear Integration allows Forceful Browsing.This issue affects OhDear Integration: from 0.0.0 before 2.0.4.
CVE-2024-13289 1 Usercentrics 1 Cookiebot \+ Gtm 2026-06-17 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Cookiebot + GTM allows Cross-Site Scripting (XSS).This issue affects Cookiebot + GTM: from 0.0.0 before 1.0.18.
CVE-2024-13288 1 Monster Menus Project 1 Monster Menus 2026-06-17 N/A 4.3 MEDIUM
Deserialization of Untrusted Data vulnerability in Drupal Monster Menus allows Object Injection.This issue affects Monster Menus: from 0.0.0 before 9.3.4, from 9.4.0 before 9.4.2.
CVE-2024-13287 1 Views Svg Animation Project 1 Views Svg Animation 2026-06-17 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Views SVG Animation allows Cross-Site Scripting (XSS).This issue affects Views SVG Animation: from 0.0.0 before 1.0.1.
CVE-2024-13286 1 Svg Embed Project 1 Svg Embed 2026-06-17 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal SVG Embed allows Cross-Site Scripting (XSS).This issue affects SVG Embed: from 0.0.0 before 2.1.2.
CVE-2024-13285 1 Wkhtmltopdf 1 Wkhtmltopdf 2026-06-17 N/A 9.8 CRITICAL
Vulnerability in Drupal wkhtmltopdf.This issue affects wkhtmltopdf: *.*.
CVE-2024-13284 1 Drupalgutenberg 1 Gutenberg 2026-06-17 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Gutenberg allows Cross Site Request Forgery.This issue affects Gutenberg: from 0.0.0 before 2.13.0, from 3.0.0 before 3.0.5.
CVE-2024-13283 1 Facets Project 1 Facets 2026-06-17 N/A 6.1 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Facets allows Cross-Site Scripting (XSS).This issue affects Facets: from 0.0.0 before 2.0.9.
CVE-2024-13282 1 Block Permissions Project 1 Block Permissions 2026-06-17 N/A 8.8 HIGH
Incorrect Authorization vulnerability in Drupal Block permissions allows Forceful Browsing.This issue affects Block permissions: from 1.0.0 before 1.2.0.
CVE-2024-13281 1 Monster Menus Project 1 Monster Menus 2026-06-17 N/A 9.1 CRITICAL
Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue affects Monster Menus: from 0.0.0 before 9.3.2.
CVE-2024-13280 1 Persistent Login Project 1 Persistent Login 2026-06-17 N/A 9.8 CRITICAL
Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Persistent Login: from 0.0.0 before 1.8.0, from 2.0.* before 2.2.2.
CVE-2024-13279 1 Two-factor Authentication Project 1 Two-factor Authentication 2026-06-17 N/A 9.8 CRITICAL
Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.8.0.
CVE-2024-13278 1 Diff Project 1 Diff 2026-06-17 N/A 9.1 CRITICAL
Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 before 1.8.0.
CVE-2024-13277 1 Smart Ip Ban Project 1 Smart Ip Ban 2026-06-17 N/A 9.1 CRITICAL
Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue affects Smart IP Ban: from 7.X-1.0 before 7.X-1.1.
CVE-2024-13276 1 File Entity Project 1 File Entity 2026-06-17 N/A 7.5 HIGH
Insertion of Sensitive Information Into Sent Data vulnerability in Drupal File Entity (fieldable files) allows Forceful Browsing.This issue affects File Entity (fieldable files): from 7.X-* before 7.X-2.39.
CVE-2024-13275 1 Security Kit Project 1 Security Kit 2026-06-17 N/A 5.3 MEDIUM
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Drupal Security Kit allows HTTP DoS.This issue affects Security Kit: from 0.0.0 before 2.0.3.
CVE-2024-13274 1 Getopensocial 1 Open Social 2026-06-17 N/A 5.3 MEDIUM
Improper Control of Interaction Frequency vulnerability in Drupal Open Social allows Functionality Misuse.This issue affects Open Social: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5.
CVE-2024-13273 1 Getopensocial 1 Open Social 2026-06-17 N/A 5.4 MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Open Social allows Cross-Site Scripting (XSS).This issue affects Open Social: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5, from 13.0.0 before 13.0.0-alpha11.
CVE-2024-13271 1 Content Entity Clone Project 1 Content Entity Clone 2026-06-17 N/A 4.3 MEDIUM
Incorrect Authorization vulnerability in Drupal Content Entity Clone allows Forceful Browsing.This issue affects Content Entity Clone: from 0.0.0 before 1.0.4.
CVE-2024-13270 1 Freelinking Project 1 Freelinking 2026-06-17 N/A 4.3 MEDIUM
Incorrect Authorization vulnerability in Drupal Freelinking allows Forceful Browsing.This issue affects Freelinking: from 0.0.0 before 4.0.1.